Gitea 在 1.27.1 之前的版本中,存在通过 diffpatch API 利用 Git 钩子(hook)安装机制实现远程代码执行(RCE)的漏洞。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | Gitea versions 1.17 through 1.27.0 contain a remote code execution vulnerability in the diffpatch endpoint caused by an add/add collision that writes an executable Git hook into the bare repository's GIT_DIR. An attacker with write access can execute arbitrary commands as the Gitea service account, exploit requires only open registration for unauthenticated access. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2026/CVE-2026-60004.yaml | POC Details |
No comments yet